Under what circumstances is a full push from Panorama required?
3685
Created On 06/24/25 01:33 AM - Last Modified 08/16/25 03:13 AM
Question
- Panorama can be used to perform selective push or full push to managed firewalls.
- Under what circumstances is a full push from Panorama required?
Environment
- Panorama managed Firewalls
- PAN-OS 10.2 and above
- Commit and Push operation
Answer
The actions below requires a full push (Push All Changes):
- A managed firewall is newly onboarded to Panorama
- Before a managed firewall is upgraded or downgraded to a version that supports Selective Push (PAN-OS 10.2+).
- The config versions on the managed firewalls are outside of the Config Audit Window.
- A configuration is loaded partially or fully into Panorama.
- A Device configuration is imported into Panorama.
- Security policies are moved across Device Groups.
- Templates, Template Stacks or Device Groups are renamed.
- Panorama HA failover is performed.
Perform a full push from Panorama.
- Go to Commit.
- Click on Push to Devices.
- Select the option Push All changes.
- (optional) Edit the selection to push only to the specific device(s).
- Click on Push.
Additional Information
Export and Push to Mutli-Vsys NGFW cause duplicates Vsyses entries